// For flags

CVE-2009-4644

 

Severity Score

9.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Accellion Secure File Transfer Appliance before 8_0_105 allows remote authenticated administrators to bypass the restricted shell and execute arbitrary commands via shell metacharacters to the ping command, as demonstrated by modifying the cli program.

Accellion Secure File Transfer Appliance anterior a v8_0_105 permite a los administradores remotos autenticados evitar el shell restringido y ejecutar comandos a su elección mediante metacaracteres en el comando ping, como lo demuestra la modificación del programa cli.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-02-19 CVE Reserved
  • 2010-02-19 CVE Published
  • 2024-04-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Accellion
Search vendor "Accellion"
Secure File Transfer Appliance
Search vendor "Accellion" for product "Secure File Transfer Appliance"
7_0_135
Search vendor "Accellion" for product "Secure File Transfer Appliance" and version "7_0_135"
-
Affected
Accellion
Search vendor "Accellion"
Secure File Transfer Appliance
Search vendor "Accellion" for product "Secure File Transfer Appliance"
7_0_178
Search vendor "Accellion" for product "Secure File Transfer Appliance" and version "7_0_178"
-
Affected
Accellion
Search vendor "Accellion"
Secure File Transfer Appliance
Search vendor "Accellion" for product "Secure File Transfer Appliance"
7_0_189
Search vendor "Accellion" for product "Secure File Transfer Appliance" and version "7_0_189"
-
Affected
Accellion
Search vendor "Accellion"
Secure File Transfer Appliance
Search vendor "Accellion" for product "Secure File Transfer Appliance"
7_0_259
Search vendor "Accellion" for product "Secure File Transfer Appliance" and version "7_0_259"
-
Affected
Accellion
Search vendor "Accellion"
Secure File Transfer Appliance
Search vendor "Accellion" for product "Secure File Transfer Appliance"
7_0_296
Search vendor "Accellion" for product "Secure File Transfer Appliance" and version "7_0_296"
-
Affected